Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 5 respecto a la semana anterior
Críticas / altas1274▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
3702 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.84% | — | Github Enterprise Server | 2/3/2023 | 17/6/2026 | A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability, an attacker would need existing permission to control the value of… | |
| Modificada | Media (6.5) | 0.57% | — | MV Idigital Clinic Enterprise Project MV Idigital Clinic Enterprise | 27/2/2023 | 17/6/2026 | MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext. | |
| Modificada | Crítica (9.8) | 12% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.9% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code. | |
| Modificada | Media (5.4) | 0.46% | — | Sandhillsdev Easy Digital Downloads | 21/2/2023 | 17/6/2026 | The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.5) | 0.68% | — | Github Enterprise Server | 16/2/2023 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected… | |
| Modificada | Alta (7.8) | 0.39% | — | GIT FOR Windows Project GIT FOR Windows | 14/2/2023 | 17/6/2026 | Git para Windows es el puerto de Windows del sistema de control de revisiones Git. Antes de Git para Windows versión 2.39.2, cuando `gitk` se ejecuta en Windows, potencialmente ejecuta archivos ejecutables del directorio actual sin darse cuenta, lo que puede explotarse con algo de ingeniería social para engañar a los… | |
| Modificada | Alta (7.3) | 0.35% | — | GIT FOR Windows Project GIT FOR Windows | 14/2/2023 | 17/6/2026 | Git para Windows es el puerto de Windows del sistema de control de revisiones Git. Antes de Git para Windows versión 2.39.2, al crear cuidadosamente la DLL y colocarla en un subdirectorio con un nombre específico junto al instalador de Git para Windows, se podía engañar a Windows para que cargara dicha DLL.… | |
| Modificada | Alta (7.5) | 1.1% | 💥 PoC | Git-scm GIT | 14/2/2023 | 8/10/2026 | Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been… | |
| Modificada | Media (5.5) | 0.71% | 💥 PoC | Git-scm GIT | 14/2/2023 | 8/10/2026 | Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone optimization even when using a non-local transport. Though Git will abort local clones whose source… | |
| Modificada | Alta (7.5) | 1.2% | — | Gitlab | 13/2/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart. | |
| Modificada | Alta (8.1) | 0.45% | — | Gitlab | 13/2/2023 | 17/6/2026 | A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project. | |
| Modificada | Alta (7.5) | 1.2% | — | Gitlab | 13/2/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. An attacker may upload a crafted CI job artifact zip file in a project that uses dynamic child pipelines and make a sidekiq… | |
| Modificada | Media (6.5) | 1.2% | — | Gitlab | 13/2/2023 | 17/6/2026 | A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage. | |
| Modificada | Crítica (9.8) | 0.81% | — | Westerndigital MY Cloud OS | 6/2/2023 | 17/6/2026 | Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files. | |
| Modificada | Alta (8.8) | 1.0% | — | Westerndigital MY Cloud OS | 6/2/2023 | 17/6/2026 | Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation. | |
| Modificada | Crítica (9.8) | 1.2% | — | Westerndigital MY Cloud OS | 6/2/2023 | 17/6/2026 | Western Digital My Cloud devices before OS5 have a nobody account with a blank password. | |
| Modificada | Media (6.5) | 0.64% | — | Gitlab Dast API Scanner | 1/2/2023 | 17/6/2026 | A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+283 | 30/1/2023 | 17/6/2026 | Un desbordamiento del búfer en WMI SMI Handler en algunos modelos de Lenovo puede permitir que un atacante con acceso local y privilegios elevados ejecute código arbitrario. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+143 | 30/1/2023 | 17/6/2026 | Una vulnerabilidad de fuga de información en SMI Handler utilizado para configurar los ajustes de la plataforma a través de WMI en algunos modelos de Lenovo puede permitir que un atacante con acceso local y privilegios elevados lea la memoria SMM. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+132 | 30/1/2023 | 17/6/2026 | Una vulnerabilidad de fuga de información en el controlador Smart USB Protection SMI Handler en algunos modelos de Lenovo puede permitir que un atacante con acceso local y privilegios elevados lea la memoria SMM. | |
| Modificada | Media (5.3) | 0.49% | — | Gitlab | 27/1/2023 | 17/6/2026 | Se identificó un problema de fuga de información en todas las versiones de GitLab EE desde la 13.7 anterior a la 15.4.6, la 15.5 anterior a la 15.5.5 y la 15.6 anterior a la 15.6.1 que expone la identificación del correo electrónico del usuario a través de el payload del webhook. | |
| Modificada | Alta (7.5) | 0.60% | — | Gitlab | 27/1/2023 | 17/6/2026 | En Gitlab EE/CE anterior a 15.6.1, 15.5.5 y 15.4.6, el uso de una rama con un nombre hexadecimal podía anular un hash existente. | |
| Modificada | Media (5.3) | 0.55% | — | Gitlab | 27/1/2023 | 17/6/2026 | Un blind SSRF en GitLab CE/EE que afecta a todas las versiones 11.3 anteriores a 15.4.6, 15.5 anteriores a 15.5.5 y 15.6 anteriores a 15.6.1 permite a un atacante conectarse a direcciones locales al configurar un GitLab Runner malicioso. | |
| Modificada | Media (4.3) | 0.75% | — | Gitlab | 27/1/2023 | 17/6/2026 | Se identificó una vulnerabilidad blind SSRF en todas las versiones de GitLab EE anteriores a 15.4.6, 15.5 anteriores a 15.5.5 y 15.6 anteriores a 15.6.1 que permite a un atacante conectarse a un host local. |